Privacy policy | Ledger (2024)

Last update: November 2023

At Ledger, we are committed to creating products that provide the highest level of security for your crypto assets but that also allow you to manage them easily. To do this, we provide you with a software application (Ledger Live) and websites (ledgerwallet.com and ledger.com) (our ‘Services’).

We can collect personal data about you when you use these Services. We have created this Confidentiality Policy to explain what we do with it.

Please note: the vault.ledger.com website is not covered by this Confidentiality Policy.

What is personal data?
Personal data (‘Data’) is information that makes it possible to identify you:

  • directly, such as your name or email address;
  • or indirectly, such as your customer number or IP address.

When do we collect your data and why?

We collect your Data when you use our Services.

We store your Data only for the time needed to carry out the operations for which it was collected, except when we need to assert our legal rights or are legally required to retain it for a different period of time. At the end of these retention periods, your Data is erased or anonymised.

Data collected through our websites

User action Data collected Data usage Reason for processing (legal basis) Retention period
Purchase of a Ledger product Name, email address, delivery and billing address, phone number, company name, intra-community VAT number, product bought, delivery method and payment, order amount, currency Invoicing, delivery, analytics and sending service notifications Performance of the contract you agreed upon buying one of our products Active database: 3 months from delivery of the product Archive: 10 years (accounting obligations)
Request to receive marketing emails (including our newsletter) Email address, campaign number, logs Sending emails on our latest developments, promotions and customer surveys Consent to receive marketing emails 3 years from the request
Request sent to customer services (on the dedicated platform or through social media) Name, email and postal address, telephone number (for product exchanges), Handle used on social media, content of our exchanges, identification document (if verification is necessary) Processing the request, quality control, verifying information is correct and preventing fraud Ledger’s legitimate interest 5 years from the request
Browsing our websites
Please note: We collect your Browsing Data using various technologies such as cookies (for more information, please visit our Cookie Policy).
Consent or refusal to save cookies on your device Cookies are saved (or not saved) on the device Legitimate interest 6 months from the user’s decision
IP address, operating system, browser, devices used, date and time of visit, URLs of clickstream to, through and from our website, products viewed and searched, download errors, duration of visit on certain pages, interaction between pages Bug-fixing, analytics, combating fraud, personalising your experience, displaying adverts on third-party websites Dependent on the purpose of the cookies saved: - Legitimate interest for technical cookies - Consent for functional, performance and advertising cookies The time needed to fulfil the purpose of the cookies saved (for example, one session for session cookies)
Participation in customer surveys Name, age, email address, family situation, profession, country, product opinion, comments Carrying out marketing studies, improving our products and services Legitimate interest 6 months from the end of the survey
Request to be re-contacted on the subject of our B2B products Name, company, role, email address, telephone number, country Making contact, sending emails on our latest developments, promotions and customer surveys Legitimate interest 5 years from the request
Signing up to our affiliate programme Name, email address, company, BTC address, identity document, intra-community VAT number and proof of residence (where required). Managing the programme, sending emails on the programme’s latest developments, remuneration Performance of the contract you agreed with Ledger when signing up to the programme For as long as the affiliate is a member of the programme, except in the event of prolonged inactivity

Please note: your payment information is collected directly by our payment providers. Ledger only has access to a truncated version of this information for anti-fraud purposes.

Data collected through our Ledger Live application

User action Data collected Data usage Reason for processing (legal basis) Retention period
Use of Ledger Live Device session identifier, IP address*, clicks, actions (e.g. launching the application, use of transactional functionalities, pages viewed), properties (e.g. type, version, language and region recorded for your operating system), currency, time stamp, amount and status of transactions, transaction identifier, identifier used by our partners to identify you (when you use their services) Bug-fixing, analytics to improve our products and services and identify additional services and functionalities you might need, processing requests for assistance, finding and preventing security problems, fraudulent activity and violations, optimising marketing operations (e.g. information on the most-used functionalities) and sending important information (e.g. security notifications). Legitimate interest 5 years from collection
Participating in our referral programme ETH address (for authentication purposes only / data not stored), UUID, BTC address Managing the programme, reward redemption Performance of the contract you agreed with Ledger by participating in the programme Active database; for as long as the referrer is a member of the programme, except in the event of prolonged inactivity
Archive: 10 years (tax and accounting obligations)

Please note: Ledger Live does not contain identifying information that allows us to know your identity.(*Your IP address is only collected to be transmitted to our partners when this information is required to provide their services, and is not stored by Ledger) Ledger neither stores nor has access to your crypto assets and private keys. We only provide ‘cold storage’ services.

Data collected by third parties accessible from Ledger Live

Below are several concrete examples:
You use our partners’ services: information (like your name, date of birth, postal address and IP address) can be collected by our partners (or by Ledger on their behalf) to meet their anti-money laundering and customer-identification obligations.
You are a validator for a proof of stake-type service: we display your name/handle, the balances delegated or any information communicated on Ledger Live.

Please note: Ledger is not responsible for the way in which our partners use your Data. If you have any questions on this subject, please consult their confidentiality policy.

Please note: Ledger never sells your Data to third parties and we prohibit our service providers from re-using it for their own behalf.

Where do we store your Data?

Your Data is stored in France, but we might have to transfer it to countries located outside of the European Economic Area.

We only transfer your Data to companies:

  • That are established in a country recognised by the European Commission as offering an adequate level of protection, or
  • With which we have signed the European Commission’s standard contractual clauses, or
  • That commit to apply a code of conduct or a certification mechanism validated by the competent European authorities.

How do we keep your Data secure?

We implement all technical and organisational measures we deem necessary to safeguard your Data at an appropriate level of security, including:

  • Payment information security: your payment information is encrypted using a secure commercial Internet protocol (TLS) and is never stored on our server.
  • An awareness programme and employee training.
  • Encryption during exchanges and storage.
  • Regular audits of data hosting companies.
  • Data redundancy for more resilience in the event of catastrophe.
  • Role-based authentication.
  • Two-factor authentication for our authorised contributors.
  • Continuous monitoring of the system.
  • Security assessments in line with industry standards.
  • Security tests and intrusion tests by independent third parties.

To assess the level of appropriate security, we take into account, among other things, the nature of the Data and the risks its processing presents. Although we strive to ensure an optimal protection of your Data, we would remind you that transmitting information on the Internet is not entirely secure.

Please note: Ledger does not have access to your passwords, PIN codes and recovery phrases. You are therefore solely responsible for keeping these confidential.

You can exercise your rights over your Data – this is how to do it!

If you want to ... All you have to do is...

Withdraw your consent

  • Upon receiving marketing emails (including our newsletter)
  • Upon the saving of cookies on your device
  • Click on the ‘Unsubscribe’ link in the footer of the emails you receive
  • Consult our Cookies Policy

Obtain a copy of your Data (in a format that can be used by third parties)

Make a request on our customer services website

Modify your Data if it is incorrect or incomplete

Make a request on our customer services website

Delete your Data (in certain cases)

Make a request on our customer services website

Object to the processing of your Data

  • Analytics and bug-fixing when browsing on Ledger Live
  • Other cases
  • Change the settings in Ledger Live
  • Make a request on our customer services website

Limit the processing of your Data (particularly if you do not want it to be deleted)

Make a request on our customer services website

Upon receiving a request, we may have to ask you for an identity document if you need to confirm your identity.If, after contacting us, you believe that your rights have not been respected, you have the option of sending a complaint to supervisory authority in your country.

Modifications to our Confidentiality Policy

We can modify our Confidentiality Policy if we deem it necessary or if the law requires it, and you accept these modifications in continuing to use our Services.

Contact

If you have any questions, do not hesitate to contact our Data Protection Officer (DPO) by making a request on our customer services website.

Stay in touch

Announcements can be found in our blog. Press contact:
[emailprotected]

Subscribe to our
newsletter

New coins supported, blog updates and exclusive offers directly in your inbox


Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time using the link included in the newsletter.

Learn more about how we manage your data and your rights.

As a seasoned expert in data privacy and security, I bring a wealth of knowledge and experience to shed light on the intricacies of Ledger's Confidentiality Policy. Having delved into various aspects of data protection and privacy policies over the years, I can confidently break down the key concepts embedded in the provided article.

Data Types and Collection: Ledger distinguishes between personal data, referred to as 'Data,' which can directly or indirectly identify individuals. Examples include names, email addresses, customer numbers, IP addresses, and more. The data collection occurs when users engage with Ledger's services, such as purchasing products, subscribing to newsletters, contacting customer services, browsing websites, participating in surveys, or signing up for affiliate programs.

Legal Basis for Data Processing: The article outlines the legal bases for processing personal data, aligning with principles such as the performance of a contract, consent, legitimate interests, and compliance with legal obligations. Ledger specifies the reasons for processing data in various scenarios, including product purchases, marketing emails, customer service requests, website browsing, surveys, and affiliate programs.

Retention Periods: Ledger defines clear retention periods for different types of data, ranging from active database storage for immediate needs to archive storage for legal and accounting obligations. For instance, customer purchase data is retained for three months from product delivery in the active database and archived for ten years.

Cookies and Browsing Data: Ledger discusses the collection of browsing data through technologies like cookies, stating the legal basis for storing cookies, the duration of storage, and the purposes such as bug-fixing, analytics, fraud prevention, and personalizing user experiences.

Security Measures: The Confidentiality Policy emphasizes Ledger's commitment to data security, highlighting technical and organizational measures. These include encryption, regular audits, data redundancy, role-based authentication, two-factor authentication, security assessments, and continuous monitoring. Ledger assures users that it does not have access to passwords, PIN codes, or recovery phrases, emphasizing user responsibility for keeping such information confidential.

User Rights: The article empowers users by detailing how they can exercise their rights over their data. This includes withdrawing consent, obtaining a copy of their data, modifying incorrect or incomplete data, deleting data in certain cases, objecting to processing, and limiting processing. Ledger provides a clear process for users to follow to enact these rights.

Data Transfer and International Storage: Ledger transparently informs users that their data may be transferred to countries outside the European Economic Area but assures that such transfers comply with data protection regulations.

Third-Party Data Collection: The article addresses data collected by third parties accessible through Ledger Live and explicitly states that Ledger is not responsible for how partners use user data. It also reassures users that Ledger does not sell their data to third parties.

Policy Modifications and Contact Information: Ledger acknowledges the possibility of modifying the Confidentiality Policy, subject to necessity or legal requirements, and communicates that continued use of services implies acceptance of such modifications. Users are encouraged to stay informed through announcements in Ledger's blog and are provided with contact information for the Data Protection Officer.

In conclusion, Ledger's Confidentiality Policy demonstrates a comprehensive approach to user data protection, outlining transparent practices, legal bases, security measures, and user rights. This robust framework aligns with best practices in the field of data privacy and security.

Privacy policy | Ledger (2024)

FAQs

What should I say in my privacy policy? ›

A privacy policy is a statement that describes how a website collects, uses, and manages the personal data of consumers. This type of policy must often include many explanations, including detailed descriptions of the who, what, where, when, and why of your data collection processes.

Does Ledger track your IP? ›

Data collected by third parties accessible from Ledger Live

You use our partners' services: information (like your name, date of birth, postal address and IP address) can be collected by our partners (or by Ledger on their behalf) to meet their anti-money laundering and customer-identification obligations.

What does a privacy policy say? ›

A privacy policy is a thorough explanation of how you plan to use any personal information that you collect through your mobile app or website. These policies are sometimes called privacy statements or privacy notices. They serve as legal documents meant to protect both company and consumers.

Can Ledger freeze my wallet? ›

Public blockchains, by design, do not have any authority that can freeze or retrieve funds, close accounts, or otherwise keep people from their assets. Ledger can't reverse transactions, no one can.

Is it OK to agree to privacy policy? ›

A privacy policy, on the other hand, is a legal document that explains to users how their data will be collected and used by the company and any third parties or affiliates. Remember, when you click "I agree" on these documents, your approval is legally binding.

What is an example of a privacy statement? ›

We take all reasonable precautions to protect your Personal Information from any loss or unauthorized use, access or disclosure. We will make information available to you about our policies and practices with respect to the management of your Personal Information.

Has a Ledger ever been hacked? ›

What exactly was compromised in the Ledger hack? The hack involved a phishing attack to access a former employee's NPMJS account, leading to the uploading of a malicious version of the Ledger Connect Kit library.

Can the government access your Ledger? ›

Cryptocurrency wallet Ledger's new update allows governments to access users' seed phrases via subpoena, said Pascal Gauthier, the chief executive officer of Ledger.

Does Ledger know my identity? ›

Ledger only collects what is strictly necessary to verify your identity, i.e. data extracted from your identity document (name, last name, date and place of birth), a selfie (extracted from the video capture) and, upon recovery request, a photo of your identity document.

Can I write my own privacy policy? ›

You can take a privacy policy for small businesses template and customize it to your needs. All you need to do is add your information to create a comprehensive resource that's targeted for your specific customers. You could also use a privacy policy generator instead of a template and work from there.

What is acceptance of privacy policy? ›

Privacy policy acceptance refers to the process of informing shoppers about the privacy details for your site and prompting shoppers to accept the privacy policy.

What is the right to privacy policy? ›

Legally, the right of privacy is a basic law which includes: The right of persons to be free from unwarranted publicity. Unwarranted appropriation of one's personality. Publicizing one's private affairs without a legitimate public concern.

Can I lose my crypto on Ledger? ›

If you can't access your Ledger device and you still have your 24-word recovery phrase (which hasn't been lost, stolen, or given out), you can rest assured that your crypto assets remain safe.

Is my money safe with Ledger? ›

The PIN code ensures that only you can sign transactions

Essentially, it guarantees that no one other than the wallet's owner can execute a transaction. This keeps your wallet safe from thieves in the physical world: even someone with physical access to your Ledger device can't access your funds.

Is it safe to have a Ledger Live on a phone? ›

The Ledger Live app is a safe and easy interface for managing your cryptocurrencies using your Ledger device.

What is an example of a privacy clause? ›

Sample Language:

Each Party shall comply with all applicable state, federal and foreign privacy and data protection laws that are or that may in the future be applicable to the supply of the Products and provision of related services and manufacturing activities under this Agreement.

What are the six words about privacy? ›

Truth, Confidence, Stability, Recovery, Secure, Responsible. Privacy is confidence in truth being shared about the stability of what will hold things private.

What must a privacy policy disclosure contain? ›

The Contents of the Privacy Notice

Your notice must include, where it applies to you, the following information: Categories of information collected. For example, nonpublic personal information obtained from an application or a third party such as a consumer reporting agency. Categories of information disclosed.

Top Articles
Should I Wait for a Dividend Before I Sell My Shares? - Sell My Shares
How much salary do you need to live comfortably in Canada? [2024 ]
Spectrum Gdvr-2007
Oldgamesshelf
Jordanbush Only Fans
Tlc Africa Deaths 2021
Instructional Resources
Crocodile Tears - Quest
Melfme
Over70Dating Login
Ncaaf Reference
Becky Hudson Free
12 Best Craigslist Apps for Android and iOS (2024)
Azeroth Pilot Reloaded - Addons - World of Warcraft
Craigslist Jobs Phoenix
Ladyva Is She Married
Best Food Near Detroit Airport
Missing 2023 Showtimes Near Landmark Cinemas Peoria
National Weather Service Denver Co Forecast
Navy Female Prt Standards 30 34
The Blind Showtimes Near Amc Merchants Crossing 16
Is Windbound Multiplayer
Joan M. Wallace - Baker Swan Funeral Home
Bethel Eportal
1 Filmy4Wap In
Getmnapp
Craigslist Lake Charles
Catchvideo Chrome Extension
Goodwill Of Central Iowa Outlet Des Moines Photos
Experity Installer
Kempsville Recreation Center Pool Schedule
Lincoln Financial Field, section 110, row 4, home of Philadelphia Eagles, Temple Owls, page 1
Fbsm Greenville Sc
Tmj4 Weather Milwaukee
LEGO Star Wars: Rebuild the Galaxy Review - Latest Animated Special Brings Loads of Fun With An Emotional Twist
The Ride | Rotten Tomatoes
Merge Dragons Totem Grid
The Syracuse Journal-Democrat from Syracuse, Nebraska
Muziq Najm
Is The Nun Based On a True Story?
Nsav Investorshub
Conan Exiles Armor Flexibility Kit
Hazel Moore Boobpedia
Content Page
Tommy Bahama Restaurant Bar & Store The Woodlands Menu
The Many Faces of the Craigslist Killer
Fallout 76 Fox Locations
Bluebird Valuation Appraiser Login
Hampton Inn Corbin Ky Bed Bugs
Sdn Dds
Vt Craiglist
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated:

Views: 6187

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.